Password security guide
Password Manager Guide
A password manager makes unique random passwords practical, but the vault, master credential, devices and recovery plan still require careful setup.
What a password manager solves
The manager creates and stores a different credential for every account, reducing reuse and memory pressure. Autofill can help identify the expected domain, and security reports can flag duplicate, weak or known-compromised entries. Secure sharing features are safer than sending passwords in chat.
A manager does not make every risk disappear. A compromised unlocked device, malicious extension, phishing approval or weak recovery process can still expose accounts.
How to evaluate a password manager
| Area | Questions to ask |
|---|---|
| Architecture | Where does encryption occur? What can the provider decrypt? |
| Updates | Are clients maintained and security issues handled transparently? |
| Authentication | Does it support strong MFA, passkeys or security keys? |
| Recovery | What happens if the master credential or device is lost? |
| Portability | Can you export and import without losing fields? |
| Devices | Are the browsers and operating systems you use supported? |
Create a strong master credential
The master credential must be unique and resistant to guessing. A long randomly generated passphrase can balance strength and memorability. Do not reuse an account password, a familiar quotation or a variation of an old master password.
Practice it before depending on memory, but never type it into unrelated sites. Some managers cannot recover it by design, so understand the provider model before migration.
Enable strong MFA and secure recovery
Prefer a phishing-resistant factor such as a security key or supported passkey, with a second safe method for recovery. Authenticator apps are also useful. Keep recovery codes or emergency kits offline in a protected location separate from the main device.
Do not remove the old factor until the new one works from another authorized device. Review account email and phone recovery details at the same time.
Migrate without lockout
- Set up the manager and recovery first.
- Import or add a small group of accounts.
- Verify URLs and remove obsolete duplicates.
- Replace reused passwords, beginning with email and financial accounts.
- Test sign-in before deleting old records.
- Securely remove temporary export files.
Exports are often plaintext. Create them only when necessary, keep them briefly and do not place them in an automatically synchronized folder.
Browser manager, standalone manager or enterprise system?
Built-in browser managers can be practical for individuals using one ecosystem. Standalone services may offer broader platform support, sharing and recovery features. Organizations need identity lifecycle, policy, audit, delegated recovery and access revocation.
The label matters less than the actual architecture, maintenance and fit. Avoid making a choice solely from affiliate reviews or a feature count.
Protect the devices that unlock the vault
Use current operating systems, device encryption, screen lock and a separate device login. Remove unneeded browser extensions and review manager sessions. Biometrics usually unlock a device-protected credential; they do not replace the vault encryption and recovery model.
Sharing passwords safely
Prefer separate user accounts and role-based access. When a credential must be shared, use the manager sharing function so access can be granted and revoked per person. Avoid shared master accounts, spreadsheets and messages.
Rotate a shared credential after a person or vendor loses authorization. Keep an inventory of service owners and recovery contacts.
What to do after a provider incident
Read the provider notice and technical details before taking blanket action. Update clients, review sessions, verify MFA and follow provider-specific rotation guidance. If vault data or account access may be exposed, prioritize the master credential and highest-value stored accounts.
A strong unique master credential and properly designed vault encryption provide important defense, but incident facts determine the response.
Password manager setup checklist
- Unique master credential.
- Strong MFA with a backup method.
- Recovery material stored separately.
- Current clients from official sources.
- Verified import and export process.
- No lingering plaintext export.
- Emergency access plan appropriate to the user or business.
Cloud-synced, local and self-hosted tradeoffs
Cloud synchronization simplifies multi-device access and recovery but adds a provider account and service availability dependency. A local vault offers direct file control but makes backup, synchronization and conflict handling the user’s responsibility. Self-hosting adds server maintenance, monitoring and secure update obligations.
Choose the model you can operate reliably. A theoretically elegant vault that is never backed up, patched or available during recovery is a poor practical choice.
Emergency access and inheritance
Individuals should decide how a trusted person can reach critical accounts after incapacity without giving them routine access today. Businesses need a documented break-glass process with multiple approvers, logging and prompt credential rotation after use.
Provider emergency-access features, sealed recovery material and legal estate planning solve different parts of the problem. Test the process with non-sensitive examples.
Audit the vault without creating new risk
Use built-in duplicate and weak-password reports locally or within the trusted provider workflow. Avoid exporting the vault to an unknown “security checker.” Review old accounts, incorrect URLs, duplicate records, stale sharing and obsolete recovery notes. Fix a manageable batch, confirm access, then continue.